CVE-2024-8126

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a new .htaccess file allowing them to subsequently upload arbitrary files on the affected site's server which may make remote code execution possible.
Configurations

Configuration 1 (hide)

cpe:2.3:a:advancedfilemanager:advanced_file_manager:*:*:*:*:*:wordpress:*:*

History

01 Oct 2024, 14:14

Type Values Removed Values Added
Summary
  • (es) El complemento Advanced File Manager para WordPress es vulnerable a la carga de archivos arbitrarios a través del archivo 'class_fma_connector.php' en todas las versiones hasta la 5.2.8 incluida. Esto permite que atacantes autenticados, con acceso de nivel de suscriptor o superior, y con permisos otorgados por un administrador, carguen un nuevo archivo .htaccess que les permita cargar posteriormente archivos arbitrarios en el servidor del sitio afectado, lo que puede hacer posible la ejecución remota de código.
First Time Advancedfilemanager
Advancedfilemanager advanced File Manager
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:advancedfilemanager:advanced_file_manager:*:*:*:*:*:wordpress:*:*
References () https://plugins.trac.wordpress.org/browser/file-manager-advanced/trunk/application/class_fma_connector.php?rev=3004748 - () https://plugins.trac.wordpress.org/browser/file-manager-advanced/trunk/application/class_fma_connector.php?rev=3004748 - Product
References () https://plugins.trac.wordpress.org/changeset/3157713/ - () https://plugins.trac.wordpress.org/changeset/3157713/ - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/801d6cde-f9c6-4e68-8bfc-ff8c0593372d?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/801d6cde-f9c6-4e68-8bfc-ff8c0593372d?source=cve - Third Party Advisory

26 Sep 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-26 11:15

Updated : 2024-10-01 14:14


NVD link : CVE-2024-8126

Mitre link : CVE-2024-8126

CVE.ORG link : CVE-2024-8126


JSON object : View

Products Affected

advancedfilemanager

  • advanced_file_manager
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type